We haven't employed conventional signature scanners(anti-virus, anti-spyware, anti-trojan, anti-anything) for many years. Nothing initiates on any of our sys without admin knowledge and approval. "If it can't initiate, it can't infect."
I found this to be a very good layman's explanation;
http://www.emsisoft.com/en/kb/articles/tec120710/